Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 17 February 2016

10 Mistakes to Avoid to Make Open Source More Secure

Open source is becoming more popular in the enterprise. But so are open-source vulnerabilities. Here is how you can prevent open source-related mishaps in 2016.
 
It's no secret that open source is becoming more popular in the enterprise. Organizations from service companies to manufacturers to banks are tapping open source to take advantage of factors such as lower development costs, faster time to market and simplified application deployment through containers. Mission-critical performance is no longer a major hurdle. But there's another issue with open source that is sticking in enterprises' craw—and will continue to stick throughout 2016 and beyond. That issue is security. More than 6,000 new open-source vulnerabilities have been reported since 2014. Given the fact that, according to various surveys, 98 percent of companies are using open-source software they don't even know about, it stands to reason that enterprises don't have a good handle on how to defend against this growing threat. Most organizations lack automated processes for selection and approval of new open source as it enters a code stream, as well as inventorying and tracking the use of open-source software within their code base and Linux containers. Identification of or monitoring for known open-source vulnerabilities (like Heartbleed and ShellShock) is another issue many organizations now face as their use of open source grows. Based on interviews with eWEEK, Black Duck, a provider of software that identifies open-source components and maps known open-source security vulnerabilities, offers some advice about issues enterprises should consider to prevent open source-related mishaps in 2016.

Watch the slide show 

Tuesday, 9 February 2016

Siachen Tragedy: The Trauma Is Real, But It’s Vital To Our Interests

In the early hours of 3 February, a major avalanche struck the Army post in Northern Siachen Glacier trapping 10 soldiers who have been reported to be dead. Lt. Gen Syed Ata Hasnain (Retd.) narrates the experience of the troops stationed there.

Ten more good men down; victims of Siachen Glacier’s unpredictable climatic and terrain dynamics. 19 Madras, to which the soldiers belonged, is as good a unit as any from the Indian Army’s Infantry. I have always admired these soldiers from the only infantry regiment of purely South Indian troops.

Far from any perception that may prevail that South Indians may not be great fighters in high altitude and glaciated terrain these units prove just the opposite. Climatic and terrain based accidents occur in the glacier with a regularity and unpredictability.

Luck more than anything else plays a major role in survival here. Equipment and training is in plenty but the glacier needs more than just that for survival. A few things need to be placed in perspective for the public to glean what glaciated operations really mean. And I won’t start the traditional way, by relating how Siachen became an issue between India and Pakistan

The Siachen Glacier, 75 Km in length, is a river of frozen snow/ice, many hundreds of feet deep. Its ‘snout’ is where the base camp of the Indian Army is. It is not really flat but compared to the high mountains on its flanks it is almost like a table top. The Army occupies the Glacier with its bases, smaller camps, headquarters and artillery gun positions.

Read the post

Friday, 29 January 2016

Public Key Infrastructure (PKI) Buyers Guide

With an ecosystem that is continually evolving, the demands of the security infrastructure of any organisation is being stretched.

Likewise, with the Internet of Things being a huge growth area, governments and commercial organisations must be able to deploy a toolset capable of meeting such requirements today, and be looking at vendors to grow products which have a roadmap that is tracking these requirements, to provide good solid support in the future.

This document will assist your organisations in the selection of the best PKI solution to meet their business and security needs. It outlines key questions to be considered during the selection process to ensure the aforementioned requirements are addressed. While this is not intended to be an exhaustive list, it serves as a starting place to assist you in your review process.

Download the buyer's guide

Fitness Tracker Vulnerabilities and How to Deal with Them

If Fitbit Charge users were wearing their fitness trackers when they heard the news about Fitbit user accounts being hacked, they probably saw their heart rates increase. On January 6, 2016, BuzzFeed News broke the story on how cybercriminals hacked multiple Fitbit user accounts. They changed email addresses and usernames as well as tried to swindle Fitbit out of replacement items under warranty.

The cybercriminals also gained access to Fitbit users' data, according to BuzzFeed News. The data includes activity-related metrics, such as the number of steps taken and calories burned. It also includes where users are performing those activities and what time they usually go to sleep if their devices have Global Positioning System (GPS) and sleep-tracking functionality.

This cyberattack begs the question: What are the fitness trackers' vulnerabilities and how can you deal with them? To answer it, you first need to know how they work.

How Fitness Trackers Work

Fitness trackers use various sensors that continuously generate data about the wearer. Because the devices need to be small and lightweight, they do not store or process this data. Instead, they typically use short-range wireless transmissions to send the data to smartphones (or computers) for storage. Apps on these devices analyze the data and display the results. Oftentimes, these apps also send a copy of the data to cloud-based servers hosted by the fitness tracker vendors. Besides storing the data, the vendors sometimes offer additional services, such as more detailed analyses.

Because fitness trackers work this way, there are security vulnerabilities on several fronts:

When the data is sent to the smartphone
When the data is sent to the vendor's cloud servers
When the data is stored in the cloud

10 tips for spotting a phishing email

Every day countless phishing emails are sent to unsuspecting victims all over the world. While some of these messages are so outlandish that they are obvious frauds, others can be a bit more convincing. So how do you tell the difference between a phishing message and a legitimate message? Unfortunately, there is no one single technique that works in every situation, but there are a number of things that you can look for. This article lists 10 of them.

1: The message contains a mismatched URL
2: URLs contain a misleading domain name
3: The message contains poor spelling and grammar
4: The message asks for personal information
5: The offer seems too good to be true
6: You didn't initiate the action
7: You're asked to send money to cover expenses
8: The message makes unrealistic threats
9: The message appears to be from a government agency
10: Something just doesn't look right

Read the full post

Thursday, 28 January 2016

10 social engineering exploits your users should be aware of

Hackers know your network security might be their toughest route to getting at your data. So they turn to other means... such as social engineering (SE). SE is a nontechnical method of intrusion that relies on human interaction to trick users into handing over the keys to the kingdom. Unfortunately, it works—and it works well. In fact, SE is one of the biggest threats to your company security.

What should you be on the lookout for? Here are 10 common SE ploys you and your users need to know about.

1: The familiarity exploit
2: The information exploit
3: The new hire exploit
4: The interview exploit
5: The hostile exploit
6: The body language exploit
7: The blind date exploit
8: The consultant exploit
9: The piggyback exploit
10: The tech talk exploit

Read the full post

Thursday, 21 January 2016

Hacking the Nazis: The secret story of the women who broke Hitler's codes


Of the 10,000-plus staff at the Government Code and Cypher School during World War II, two-thirds were female. Three veteran servicewomen explain what life was like as part of the code-breaking operation during World War II.

"I was given one sentence, 'We are breaking German codes, end of story'."

It was Ruth Bourne's first job out of college, when, like thousands of other young British women during World War II, she was recruited to aid the Allied cipher-breaking efforts at Bletchley Park.

Today, the mansion in the heart of the southeast English countryside is famous for being where the brilliant mathematician Alan Turing cracked the Nazi's Enigma code.

Because Turing's individual achievements were so momentous, it's sometimes forgotten that more than 10,000 other people worked at the Government Code and Cypher School, of whom more than two-thirds were female. These servicewomen played a pivotal role in an operation that decrypted millions of German messages and which is credited with significantly shortening the war.

The vital importance of preempting German plans led to a huge push to create machines that could crack ciphers at superhuman speeds. These efforts produced Colossus, the world's first programmable electronic digital computer.

However, the reality of running these electromechanical machines, setting rotors and plugging boards day in day out, was often less than thrilling, with the 18-year-old Bourne envying the girls who test-piloted aircraft fresh off the production line.

"That was exciting but standing in front of a machine for eight hours was not," she said.

As mundane as her daily routine was, it was vital in deciphering coded messages sent by the German army, navy and air force and helping the Allied forces turn the tide of war.

The problem facing Britain and its allies early in the war was that the Enigma machine used to encrypt Nazi military traffic could scramble a message in 158 million million million ways, and each day the settings used would be changed. On top of that, on an average day at Bletchley Park code-breakers were tasked with breaking between 2,000 and 6,000 messages of German, Italian, Japanese and Chinese origin. There were far too many to check by hand.

The code-breaking needed to be automated, and it fell to British mathematician and father of the computer Alan Turing, with the help of the British Tabulating Machine Company, to devise the machine for the job.

His solution was the bombe, an electromechanical machine designed to emulate the workings of 36 Enigmas.

Bourne was a member of the Women's Royal Naval Service, known as the Wrens, who were charged with preparing the machines each day, turning the drums on the front and plugging up the boards at the back according to settings laid out in a menu. These settings were derived from cribs, which were best guesses at fragments of plain text—for example, standard openings such as weather reports—from the enciphered messages.

If correct, these cribs would reveal some of the Enigma settings used to encode the message and provide a starting point for devising the remaining settings. The bombe could check the possible ways the Enigma could have been set up incredibly rapidly, dismissing incorrect settings one at a time.

If the crib and initial settings were good, then the bombe could return the information needed to crack the code within minutes.

"I joined just around D-Day and at that time the traffic was tremendous. We were breaking thousands of messages," Bourne said.

Tuesday, 19 January 2016

9 privacy and security errors startups can't afford to make

Startups are risky. There's no sense adding to the precariousness of new business ownership by making the following errors in judgment.

With lots on their mind, startup owners tend to back-burner decisions that do not help the bottom line. More often than not that includes deciding how privacy and data security should be managed. Françoise Gilbert, a partner with the law firm Greenberg Traurig, LLP suggests that is a bad idea, "A single error can undermine the trust of investors and customers, attract unwanted regulatory attention or litigation, and ultimately, derail a startup's success."

"Most startups cannot survive on their own without the help of third-party investments or contracts," continues Gilbert. "If they want to succeed and meet these third parties' requirements, they have to implement from the start and continue to use, the appropriate privacy and security safeguards that are adapted to their specific business model."

And Gilbert ought to know, in 30 years, she has seen plenty of mistakes; she outlines in her law firm's Emerging Technology Views blog what to avoid. So, startup owners, to steer clear of additional angst, here's Gilbert's list of whatnot to do.

1: Assuming privacy or security is just for the geeks
2: Ignoring relevant rules and laws
3: Thinking you are flying under the radar
4: Ignoring the benefits from policies
5: Believing you are not responsible
6: Assuming that more is better
7: Copying the privacy policy of the business next door
8: Making representations that they don't understand
9: Misunderstanding the effect of anonymization

Begin Monetising SDN & NFV Today

While excitement builds around the development of 5G and vendors jostle for position, the security landscape continues to threaten operators’ livelihoods. With the ever-increasing number of threats facing the telecoms network, guaranteeing the security of the future network is absolutely essential.

There have been some early successes for telcos implementing virtualization platforms, and this Telecoms.com Intelligence paper, in association with Cisco, will investigate these increasingly prominent technologies and how telcos could go about claiming some important and tangible business wins.

This white paper will provide readers with:
  • Tangible success stories from 3 operators implementing NFV (network function virtualization) & Cloud technologies.
  • Advise on rolling out live NFV services for real business benefit.
  • Explain how to orchestrate and manage operational VNFs on the live service provider network.

Thursday, 2 July 2015

9 Productivity Tricks for the Time-Crunched Security Professional

Security professionals are a busy bunch. Thanks to sophisticated threats, limited resources, product complexities, compliance demands and business objectives, you already are being pulled in what probably feels like a thousand directions - and that's on a good day.

Your job may never slow down. But when confronting these challenges, you can implement clever solutions that will help boost your time management, efficiency and performance to get things done. Much of the advice out there for improving productivity is repeated over and over (arriving at the office early, limiting meetings, taking regular "fresh air" breaks) - but much less available are suggestions specific to security careers.

Here are nine actionable "hacks" that will help you pick up your game and optimize your infosec routine, all while sharpening both your hard and soft skills in the process.

Efficiency tools
Outsource resource-consuming work
Threat feeds and lists
Data breach repositories
Security stats
Virtualization
Coding
ModSecurity
McCumber cube

Read the full post

Tuesday, 13 January 2015

7 security mistakes people make with their mobile device

Mobile devices, especially smartphones, have ushered businesses into a new era of productivity and working on-the-go. But with those advances and added convenience comes a wealth of security blunders just waiting to happen. Here are some of the worst mistakes users can make with their mobile devices and how to avoid them.

Failing to lock down your device
Not having the most up to date versions of your apps
Storing sensitive, work-related data on an unauthorized device
Opening questionable content
Not adhering to your company's social media policies
Not equipping employees' devices with some form of MDM or encryption
Using public or unsecure Wi-Fi

Read Full Post

Saturday, 9 February 2013

7 Innovative Solutions to CAPTCHA User Attention

Among the many solutions that Web workers have devised to improve security measures, as well as the user experience on their sites, is the CAPTCHA (or Completely Automated Public Turing test to tell Computers and Humans Apart), a solution that presents a challenge response test to users that ensures the “person” trying to access the site is actually a human, and not just an annoying spam bot.

Unfortunately, while these solutions can be useful in theory, they are often more problematic when they’re actually implemented. Not only can they be cumbersome, difficult to read and a generally unwanted hassle for users, but they’re not even foolproof, as bots can use optical character recognition (OCR) software to crack the CAPTCHA code.

As a result, developers have had to get creative with their CAPTCHAs, resulting in an improved experience for many users. This post presents seven of the more interesting, innovative and just plain useful CAPTCHA solutions available today.

Read the full post

Monday, 7 January 2013

Security Resolutions for 2013

Among your typical New Year's resolutions--lose weight, stop smoking, be happier--you should consider making some pledges to better secure your digital life. You might even be healthier if you can prevent the stress of a digital disaster, like malware wiping out your PC, having your online accounts hacked, or becoming a victim of identify theft because of a phishing scam or data theft. With that in mind, here are some security resolutions you should consider for the new year.

Use PIN protection on your mobile devices
Install an anti-theft app on your mobile devices
The same goes for your laptop
Perform PC security checks
Encrypt your laptop
Encrypt your USB drives
Secure your social network accounts
Sign up for online backups
Install a two-way firewall
Use OpenDNS for content filtering
Check your Wi-Fi security

Read the resolutions

Monday, 26 November 2012

7 Lessons on Cloud Security

Though the benefits of the cloud to business are several in number, many organizations are still hesitant to leverage it for business growth, thanks to various misconceptions on cloud security. Here's our guide that gives you a better understanding on the topic.

1. What You Really Need to Know about Cloud Security
2. Cloud Security: Ten Questions to Ask before You Jump in
3. Top Five Key Cloud Security Issues
4. Cloud CIO: The Two Biggest Lies About Cloud Security
5. 10 Ways to Ease Public Cloud Security Concerns
6. Cloud Computing Tools: Improving Security through Visibility and Automation
7. Security in the Cloud is All about Visibility and Control

Read the full post

Wednesday, 31 October 2012

Gartner: How Big Trends in Security, Mobile, Big data and Cloud will Change IT

When you go to a Gartner conference one of he main things you'll notice is the sheer volume of data they can generate on just about any IT topic. The recent Gartner Symposium/ITxpo in Orlando, Fla., was no different. The conference, attended by some 9,000 executives focused on the changes security challenges, mobile computing, big data and cloud will be bringing to IT in the near future.

Trying to get through it all can be daunting so we've tried to simplify that process by distilling a variety of Gartner ITxpo presentations and coming up with the most salient information.

So here goes. From the Gartner analysts, presentations on:

Read the full story

Friday, 26 October 2012

Windows 8 Cheat Sheet & Security features

This post presents in a Q&A format what you need to know about the most radical redesign since Windows 95.

Cheet Sheet

What you should know about Windows 8 security features

Saturday, 29 September 2012

9 Dirty Tricks: Social Engineers' Favorite Pick-Up Lines

What the average guy might call a con is known in the security world as social engineering. Social engineering is the criminal art of scamming a person into doing something or divulging sensitive information. These days, there are thousands of ways for con artists to pull off their tricks (See: Social Engineering: Eight Common Tactics). Here the author Joan Goodchild looks at some of the most common lines these people are using to fool their victims.

Full article

19 Ways to Build Physical Security into a Data Center

There are plenty of complicated documents that can guide companies through the process of designing a secure data center—from the gold-standard specs used by the federal government to build sensitive facilities like embassies, to infrastructure standards published by industry groups like the Telecommunications Industry Association, to safety requirements from the likes of the National Fire Protection Association. But what should be the CSO's high-level goals for making sure that security for the new data center is built into the designs, instead of being an expensive or ineffectual afterthought?

Read below to find out how a fictional data center is designed to withstand everything from corporate espionage artists to terrorists to natural disasters. Sure, the extra precautions can be expensive. But they're simply part of the cost of building a secure facility that also can keep humming through disasters.

Read the full article

Monday, 24 September 2012

WhiteHat Security Website Statistics Report 2012: How Does Your Website Security Stack Up Against Your Peers?

Website security is a moving target. New attacks techniques are frequently disclosed. New website launches are common. New Web technologies are made available every day. New application code is released constantly. Enterprises need timely information about how they can best defend their websites, gain visibility into their vulnerability lifecycle, measure the performance of their security programs, and determine how they compare to their industry peers. Establishing these metrics is crucial towards improving enterprise security.

The WhiteHat Security report presents a statistical picture of current website vulnerabilities among 7,000 websites, across hundreds of organization, and is accompanied by WhiteHat expert analysis and recommendations. WhiteHat’s report is the only one that focuses solely on unknown vulnerabilities in custom Web applications, code unique to an organization, within real-world websites and does so over time.

Download the report

Tuesday, 28 August 2012

IT's 9 Biggest Security Threats

Years ago the typical hacking scenario involved a lone attacker and maybe some buddies working late at night on Mountain Dew, looking for public-facing IP addresses. When they found one, they enumerated the advertising services (Web server, SQL server, and so on), broke in using a multitude of vulnerabilities, then explored the compromised company to their heart's content. Often their intent was exploratory. If they did something illegal, it was typically a spur-of-the-moment crime of opportunity.

My, how times have changed.

When describing a typical hacking scenario, these days you must begin well before the hack or even the hacker, with the organization behind the attack. Today, hacking is all crime, all the time, complete with bidding markets for malware, crime syndicates, botnets for hire, and cyber warfare gone amok.

Here are the nine biggest threats facing today's IT security pros as outlined by Roger A. Grimes.

Threat No. 1: Cyber crime syndicates
Threat No. 2: Small-time cons -- and the money mules and launders supporting them
Threat No. 3: Hacktivists
Threat No. 4: Intellectual property theft and corporate espionage
Threat No. 5: Malware mercenaries
Threat No. 6: Botnets as a service
Threat No. 7: All-in-one malware
Threat No. 8: The increasingly compromised Web
Threat No. 9: Cyber warfare

Read the full post